From b41ca6465cbeb80aec6b91d485ca4f92b793ec8c Mon Sep 17 00:00:00 2001 From: Jenkins Server Date: Sat, 5 Sep 2026 13:32:27 +0200 Subject: [PATCH] Recommit for updates in build 9 --- .vscode/settings.json | 19 ------- Jenkinsfile | 127 ------------------------------------------ doc/file.README.html | 34 ++++++++++- doc/index.html | 34 ++++++++++- 4 files changed, 62 insertions(+), 152 deletions(-) delete mode 100644 .vscode/settings.json delete mode 100644 Jenkinsfile diff --git a/.vscode/settings.json b/.vscode/settings.json deleted file mode 100644 index 1e87f6f..0000000 --- a/.vscode/settings.json +++ /dev/null @@ -1,19 +0,0 @@ -{ - "cSpell.words": [ - "allowdupe", - "dontlognull", - "dport", - "forwardfor", - "httplog", - "managehome", - "maxconn", - "nologin", - "pidfile", - "redispatch", - "roundrobin", - "sess", - "setsebool", - "tcplog", - "userlist" - ] -} \ No newline at end of file diff --git a/Jenkinsfile b/Jenkinsfile deleted file mode 100644 index 512e8e6..0000000 --- a/Jenkinsfile +++ /dev/null @@ -1,127 +0,0 @@ -pipeline { - agent { - label 'puppet' - } - - post { - always { - deleteDir() /* clean up our workspace */ - } - success { - updateGitlabCommitStatus state: 'success' - } - failure { - updateGitlabCommitStatus state: 'failed' - step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true]) - } - } - - options { - gitLabConnection('gitlab.confdroid.com') - } - - stages { - - stage('pull master') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - # Ensure we're on the development branch (triggered by push) - git checkout development - # Create jenkins branch from development - git checkout -b jenkins-build-$BUILD_NUMBER - # Optionally merge master into jenkins to ensure compatibility - git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; } - ''' - } - } - } - - stage('puppet parser') { - steps { - sh '''for file in $(find . -iname \'*.pp\'); do - /opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1; - done;''' - } - } - - stage('check templates') { - steps{ - sh '''for file in $(find . -iname \'*.erb\'); - do erb -P -x -T "-" $file | ruby -c || exit 1; - done;''' - } - } - - stage('puppet-lint') { - steps { - sh '''/usr/local/bin/puppet-lint . \\ - --no-variable_scope-check \\ - || { echo "Puppet lint failed"; exit 1; } - ''' - } - } - - stage('SonarScan') { - steps { - withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) { - sh ''' - /opt/sonar-scanner/bin/sonar-scanner \ - -Dsonar.projectKey=confdroid_haproxy \ - -Dsonar.sources=. \ - -Dsonar.host.url=https://sonarqube.confdroid.com \ - -Dsonar.token=$SONAR_TOKEN - ''' - } - } - } - - stage('create Puppet documentation') { - steps { - sh '/opt/puppetlabs/bin/puppet strings' - } - } - - stage('update repo') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit" - git push origin HEAD:master - ''' - } - } - } - stage('Mirror to Gitea') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - withCredentials([usernamePassword( - credentialsId: 'Jenkins-gitea', - usernameVariable: 'GITEA_USER', - passwordVariable: 'GITEA_TOKEN')]) { - script { - // Checkout from GitLab (already done implicitly) - sh ''' - git checkout master - git pull origin master - git branch -D development - git branch -D jenkins-build-$BUILD_NUMBER - git rm -f Jenkinsfile - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git commit --amend --no-edit --allow-empty - git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_haproxy.git - git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \ - push master --mirror - ''' - } - } - } - } - } - } -} \ No newline at end of file diff --git a/doc/file.README.html b/doc/file.README.html index e9f2bbf..e991a83 100644 --- a/doc/file.README.html +++ b/doc/file.README.html @@ -78,6 +78,8 @@
  • Proxy Configuration

  • +

    TLS

    +
  • SELINUX

  • Known Problems

    @@ -126,7 +128,7 @@
  • ACL options

  • -

    manage fail2ban integration (optional, requires fail2ban_cd module)

    +

    manage fail2ban integration (optional, requires confdroid_fail2ban module)

  • SERVICE

    @@ -140,8 +142,6 @@

    All dependencies must be included in the catalogue.

    @@ -172,6 +172,8 @@

    The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:

    +

    ACL rule:

    +
    confdroid_haproxy::server::proxy { 'testing':
         haproxy_fqdn    =>  'node.example.net',
         frontend_name   =>  'test01-frontend',
    @@ -182,8 +184,34 @@
       }
     
    +

    real Proxy for https:

    + +
    haproxy_cd::server::proxy { 'https-in':
    +    haproxy_fqdn    => 'node.example.net',
    +    frontend_name   => 'https-in',
    +    frontend_mode   => 'http',
    +    fe_bind_mode    => '*:443 ssl crt /etc/haproxy/certs/',
    +    fe_option       => 'forwardfor',
    +    fe_http_request => 'add-header X-Forwarded-Proto https',
    +    acl_rule_front  => 'host_grafana hdr(host) -i grafana.example.net',
    +    fe_use_backend  => 'grafana_backend if host_grafana',
    +    backend_configs => [
    +      {
    +        'backend_name'         => 'grafana_backend',
    +        'be_mode'              => 'http',
    +        'be_balance'           => 'roundrobin',
    +        'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
    +      }
    +    ]
    +  default_backend => 'error_backend',
    +
    +

    This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. haproxy_fqdn must- contain the fqdn of the haproxy server- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.

    +

    TLS

    + +

    Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. This module is NOT managing certificates, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.

    +

    SELINUX

    All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module), the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it. This is the default setting.

    diff --git a/doc/index.html b/doc/index.html index 16616b5..79f4334 100644 --- a/doc/index.html +++ b/doc/index.html @@ -78,6 +78,8 @@
  • Proxy Configuration

  • +

    TLS

    +
  • SELINUX

  • Known Problems

    @@ -126,7 +128,7 @@
  • ACL options

  • -

    manage fail2ban integration (optional, requires fail2ban_cd module)

    +

    manage fail2ban integration (optional, requires confdroid_fail2ban module)

  • SERVICE

    @@ -140,8 +142,6 @@

    All dependencies must be included in the catalogue.

    @@ -172,6 +172,8 @@

    The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:

    +

    ACL rule:

    +
    confdroid_haproxy::server::proxy { 'testing':
         haproxy_fqdn    =>  'node.example.net',
         frontend_name   =>  'test01-frontend',
    @@ -182,8 +184,34 @@
       }
     
    +

    real Proxy for https:

    + +
    haproxy_cd::server::proxy { 'https-in':
    +    haproxy_fqdn    => 'node.example.net',
    +    frontend_name   => 'https-in',
    +    frontend_mode   => 'http',
    +    fe_bind_mode    => '*:443 ssl crt /etc/haproxy/certs/',
    +    fe_option       => 'forwardfor',
    +    fe_http_request => 'add-header X-Forwarded-Proto https',
    +    acl_rule_front  => 'host_grafana hdr(host) -i grafana.example.net',
    +    fe_use_backend  => 'grafana_backend if host_grafana',
    +    backend_configs => [
    +      {
    +        'backend_name'         => 'grafana_backend',
    +        'be_mode'              => 'http',
    +        'be_balance'           => 'roundrobin',
    +        'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
    +      }
    +    ]
    +  default_backend => 'error_backend',
    +
    +

    This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. haproxy_fqdn must- contain the fqdn of the haproxy server- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.

    +

    TLS

    + +

    Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. This module is NOT managing certificates, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.

    +

    SELINUX

    All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module), the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it. This is the default setting.